๐Ÿ” CVE Alert

CVE-2026-52824

UNKNOWN 0.0

Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as kernel.secret. An unauthenticated attacker who reaches a deployment that did not override APP_SECRET, knows a username, correctly guesses the account ID associated with that username, and targets an account without active two-factor authentication can forge HMAC-protected authentication artifacts, including KIMAI_REMEMBER cookies and login links, to access the account without its password. The updated entrypoint generates and persists a random secret when no safe operator-provided value exists. This issue is fixed in version 2.58.0.

CWE CWE-1188
Vendor kimai
Product kimai
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for kimai kimai

Be the first to know when new unknown vulnerabilities affecting kimai kimai are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kimai / kimai
< 2.58.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kimai/kimai/security/advisories/GHSA-jr9p-4h4j-6c58 github.com: https://github.com/kimai/kimai/pull/5952 github.com: https://github.com/kimai/kimai/commit/31a8f887a5cda517db7b4320a7ad997c87d08601 github.com: https://github.com/kimai/kimai/releases/tag/2.58.0 kimai.org: https://www.kimai.org/en/security/ghsa-jr9p-4h4j-6c58